Sensu develops a focused monitoring and observability platform centered on its core agent and server product, which ingests metrics and events from infrastructure across networks and cloud environments. The durable signal in its disclosure history centers on access-control and information-handling weaknesses—specifically improper permission assignment for critical resources and sensitive data leakage into log files—reflecting the trust and visibility boundaries inherent to a centralized monitoring system. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sensu over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000060CRITICAL Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that ca | Feb 9, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-1000209HIGH Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may exe | Jul 13, 2018 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sensu.
Media articles that mention a CVE ID that affects a product developed by Sensu — matched by CVE ID, not by vendor name.